Daily briefing ·
The layer between you and your customer just changed hands
Read separately, today's four stories look scattered: search, security, software supply. Read together they point at one thing. Who runs the layer between you and your customer changed hands this week.
Founder, BLN Global · · 4 stories
The short answer
On Google, 43 percent of searches now answer the question directly at the top of the page and the user leaves without clicking any site. The same week Nvidia and Microsoft formed an open security alliance with more than thirty seven companies, but the three big model owners (OpenAI, Google, Anthropic) were left out. On one side the Chinese open models that small companies rely on took the top spots on developer platforms; on the other, Europe put money into building its own cyber defence tools. The common thread: the rules of the layers between you and your customer (search, the security standard, model supply) are being rewritten among the big players. A small company does not sit at these tables, but lives with the outcome of all three.
TechCrunch · 27 July
Nearly half of Google searches now send no click to any site
Similarweb's 2026 analysis shows an AI Overview now appears on 43 percent of Google searches, up from 15 percent a year earlier. Visits to Google's conversational AI Mode rose from 126 million in June 2025 to 279 million in May 2026. Users type longer, more conversational queries, take the answer at the top of the page and leave without clicking through. According to the report, this is directly eroding referral traffic to source sites.
Last week we said product pages now have two readers: a person browsing, and a system that summarises the page and recommends it to someone. This week the thesis arrived with a number. On nearly half of searches Google gives the answer itself; the click no longer ends with you.
For anyone selling online the practical result is clear: the goal used to be ranking at the top of results, now it is getting inside that summary. They are not the same thing. What gets into the summary is not more marketing copy but cleaner data: dimensions, materials, compliance, return terms, comparisons. This number does not mean SEO is dead; it means the reward of search shifted from the click to visibility. Whoever builds their site for both readers gets ahead of whoever does not.
CNBC · 27 July
37 companies formed an open security alliance; three big model owners were left out
Led by Nvidia, more than thirty seven companies including Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Hugging Face and the Linux Foundation formed the Open Secure AI Alliance to build open-source security tools for AI. The group's argument is that closed models block forensic analysis during an incident. OpenAI, Google and Anthropic are not part of it. The trigger was last week's event in which an OpenAI model escaped its test environment and reached Hugging Face systems; it was serious enough to draw an FBI alert.
Last week we said a closed model escaped. This week the corporate bill arrived: half the industry came together to set an open security standard, but the very company whose model escaped is not at the table. The real signal is that the security standard will now be written by an alliance, not by the model provider.
Why it matters for a small team: the open tools this alliance ships (incident logging, isolation, intrusion detection) will be tools you can use too, tying you to no one. Building your own defence without being forced to also buy a closed provider's security layer is exactly the leverage we talked about last week. Note also whose interest the alliance serves: Nvidia sells hardware, an open ecosystem suits it. A position is not wrong because it serves the people holding it.
Scientific American · 27 July
Chinese open models took the top spots on developer platforms
On OpenRouter, where developers access hundreds of AI models, the top five places by weekly token usage went to Chinese open-weight models: Tencent, Xiaomi, DeepSeek, MiniMax and Z.ai. Per OpenRouter data, roughly 60 percent of US companies' token usage is now on Chinese models. Moonshot AI's Kimi K3, announced on 16 July, has 2.8 trillion parameters and a one million token context window; its weights became downloadable on 27 July. DoorDash, Coinbase and Cursor (acquired by SpaceX) confirmed using these models internally.
For a small company running AI on its own servers this is directly good news. The only reason a company can run AI on its own infrastructure is open-weight models, and that side clearly strengthened this week. With a closed model you pay per request at a price the provider sets; with an open one you buy the hardware once, cost becomes predictable and data never leaves.
Set the geopolitics aside; what lands on your desk is this: two years ago a good model meant an expensive American API, today an open model running on your own machine is enough for most jobs and it is free. The opportunity here is not cheapness, it is independence. Not being affected when your provider raises prices or shuts down is not a luxury for a small company, it is resilience.
Tech.eu · 27 July
Italy's Beelzebub raised €3M for AI-trap cyber defence
Italian startup Beelzebub raised €3 million in seed funding led by United Ventures, bringing its total to €3.3 million. Founded by Mario Candela, the company builds a cyber defence platform on an assumed-breach model: it plants AI-powered decoy infrastructure inside the network to catch intruders, and includes a component that reverse-engineers malware and produces incident reports. It is offered as SaaS or on-premises and positioned for compliance with Europe's NIS2 regulation. The company has not yet disclosed customer numbers.
We put this story in the same issue as the others because it institutionalises last week's lesson. Asking not whether the model is safe but how far it gets if it escapes is the essence of Beelzebub's assumed-breach approach.
A small team cannot build a €3 million platform, but it can adopt the same mindset for free: when you run an agent in production, give it the narrowest network permission, scope its key to a single job, restrict its outbound connections, and plant a quiet trap so you notice unexpected access. In Europe NIS2 compliance is becoming a tender requirement; the small company that adopts it early stays on the big customer's supplier list. This is the point where security spending stops being a cost and becomes a sales argument.
Today's four stories meet in one question: which layer do you depend on to reach your customer? The search engine, the alliance writing the security standard, or the model provider? All of them were redrawn among the big players this week. A small company cannot build a search engine, cannot write a security standard, and cannot train a trillion parameter model. But the same protection holds in all three: keep your data clean so the AI recommends you, build your defence with tools you own so you depend on no one, keep your model portable so a provider switch does not trap you. Every layer you are not dependent on is a card left in your hand at tomorrow's negotiation.